Firefox.exe

1

Firefox.exe

offline
  • Pridružio: 10 Jan 2015
  • Poruke: 202
  • Gde živiš: Novi Sad

Napisano: 28 Mar 2015 0:44

Ovo mi non stop blokira nzm jel imam nesto ili sta se desava


Dopuna: 28 Mar 2015 0:54

desava se da par dana mi blokira stranicu i nisam siguran da li je ista ova stranica sto je sad ali znam da infekcije nisu bile iste

https://www.mycity.rs/must-login.png

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by Dezika (administrator) on DEZIKA-PC on 28-03-2015 00:44:47
Running from C:\Users\Dezika\Downloads
Loaded Profiles: Dezika (Available profiles: Dezika)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
() C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(MyCity) C:\Program Files\MCShield\MCShieldRTM.exe
(IVT Corporation.) C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(IVT Corporation.) C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil VoIP Plugin.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(BitTorrent Inc.) C:\Users\Dezika\AppData\Roaming\uTorrent\uTorrent.exe
(Ubisoft) C:\Users\Dezika\AppData\Local\Temp\{B6AEC094-C682-43C3-B9DE-E0F665D6582B}\setup.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10996368 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-12-18] (Oracle Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5511352 2015-03-19] (Avast Software s.r.o.)
HKLM\...\RunOnce: [20150107] => C:\Program Files\AVAST Software\Avast\setup\emupdate\2ed042ba-c562-4008-9702-daa01fb3f8d8.exe [183232 2015-03-27] (AVAST Software)
HKU\S-1-5-21-3609390036-2450797130-3040472919-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31087200 2015-01-23] (Skype Technologies S.A.)
HKU\S-1-5-21-3609390036-2450797130-3040472919-1000\...\Run: [MCShield Monitor] => C:\Program Files\MCShield\mcshieldrtm.exe [650816 2014-04-11] (MyCity)
HKU\S-1-5-21-3609390036-2450797130-3040472919-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5496600 2015-01-20] (Piriform Ltd)
HKU\S-1-5-21-3609390036-2450797130-3040472919-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3609390036-2450797130-3040472919-1000\...\MountPoints2: {030dcc60-bb49-11e4-a925-0015831080cf} - G:\BlacklistAutoRun.exe
HKU\S-1-5-21-3609390036-2450797130-3040472919-1000\...\MountPoints2: {e2cf5ba3-ac3d-11e4-9402-806e6f6e6963} - F:\setup.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BlueSoleil.lnk
ShortcutTarget: BlueSoleil.lnk -> C:\Program Files\IVT Corporation\BlueSoleil\gprs.exe (IVT Corporation.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (Avast Software s.r.o.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3609390036-2450797130-3040472919-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3609390036-2450797130-3040472919-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2015-02-24] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-03-14] (Avast Software s.r.o.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2015-02-24] (Oracle Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Windows\system32\Skype4COM.dll [2007-02-07] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 89.216.1.40 89.216.1.50

FireFox:
========
FF ProfilePath: C:\Users\Dezika\AppData\Roaming\Mozilla\Firefox\Profiles\1kvknn5z.default
FF DefaultSearchEngine: Google (avast)
FF DefaultSearchUrl: https://www.google.com/search/?trackid=sp-006
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Homepage: https://www.google.com/?trackid=sp-006
FF Keyword.URL: https://www.google.com/search/?trackid=sp-006
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-14] ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll No File
FF Plugin: @java.com/DTPlugin,version=10.76.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2015-02-24] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.76.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2015-02-24] (Oracle Corporation)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Dezika\AppData\Roaming\Mozilla\Firefox\Profiles\1kvknn5z.default\searchplugins\google-avast.xml [2015-02-12]
FF Extension: Adblock Plus - C:\Users\Dezika\AppData\Roaming\Mozilla\Firefox\Profiles\1kvknn5z.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-03-14]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-03-14]

Chrome:
=======
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-14]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-03-14] (Avast Software s.r.o.)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3205216 2015-03-14] (Avast Software)
R2 BlueSoleil Hid Service; C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe [166520 2007-12-27] ()
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [17536800 2014-07-25] (NVIDIA Corporation)
R2 Start BT in service; C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [51816 2007-12-27] ()
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5429520 2015-01-30] (TeamViewer GmbH)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S3 gusvc; "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24144 2015-03-14] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [73440 2015-03-14] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81728 2015-03-14] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49904 2015-03-14] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [788272 2015-03-14] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427480 2015-03-14] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [106912 2015-03-14] (Avast Software s.r.o.)
S3 aswTap; C:\Windows\System32\DRIVERS\aswTap.sys [38984 2015-02-12] (The OpenVPN Project)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [206976 2015-03-14] ()
R3 BlueletAudio; C:\Windows\System32\DRIVERS\blueletaudio.sys [34312 2007-06-24] (IVT Corporation.)
R3 BlueletSCOAudio; C:\Windows\System32\DRIVERS\BlueletSCOAudio.sys [27656 2007-06-24] (IVT Corporation.)
R3 BT; C:\Windows\System32\DRIVERS\btnetdrv.sys [18320 2007-03-05] (IVT Corporation.)
R3 Btcsrusb; C:\Windows\System32\Drivers\btcusb.sys [38920 2007-06-24] (IVT Corporation.)
R0 BTHidEnum; C:\Windows\System32\Drivers\vbtenum.sys [20880 2007-03-05] (IVT Corporation.)
R0 BTHidMgr; C:\Windows\System32\Drivers\BTHidMgr.sys [35600 2007-03-05] (IVT Corporation.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2015-02-23] (Disc Soft Ltd)
R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] () [File not signed]
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19232 2014-07-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34080 2014-03-31] (NVIDIA Corporation)
R0 speedfan; C:\Windows\System32\speedfan.sys [24184 2012-12-29] (Almico Software)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220240 2015-03-14] (Avast Software)
R3 VComm; C:\Windows\System32\DRIVERS\VComm.sys [34448 2007-03-05] (IVT Corporation.)
R3 VcommMgr; C:\Windows\System32\Drivers\VcommMgr.sys [44304 2007-03-05] (IVT Corporation.)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-28 00:44 - 2015-03-28 00:47 - 00011905 _____ () C:\Users\Dezika\Downloads\FRST.txt
2015-03-28 00:41 - 2015-03-28 00:45 - 00000000 ____D () C:\FRST
2015-03-28 00:37 - 2015-03-28 00:38 - 01135104 _____ (Farbar) C:\Users\Dezika\Downloads\FRST.exe
2015-03-27 20:26 - 2015-03-27 20:26 - 00000000 ____D () C:\ProgramData\Orbit
2015-03-27 20:15 - 2015-03-27 20:15 - 00000916 _____ () C:\Users\Dezika\Desktop\Far Cry 3.lnk
2015-03-27 20:15 - 2015-03-27 20:15 - 00000000 ____D () C:\Users\Dezika\Documents\My Games
2015-03-27 20:15 - 2015-03-27 20:15 - 00000000 ____D () C:\Users\Dezika\AppData\Roaming\Far Cry 3
2015-03-27 20:15 - 2015-03-27 20:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
2015-03-27 20:14 - 2015-03-27 20:15 - 00000000 ____D () C:\ProgramData\Package Cache
2015-03-27 16:31 - 2015-03-27 16:34 - 00000000 ____D () C:\Users\Dezika\Downloads\Godzilla (2014) [1080p]
2015-03-27 16:12 - 2015-03-27 16:14 - 00000000 ____D () C:\Users\Dezika\Downloads\Noah (2014) [1080p]
2015-03-27 11:33 - 2015-03-27 11:34 - 00057960 _____ () C:\Users\Dezika\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-26 22:48 - 2015-03-27 11:32 - 00000336 _____ () C:\Windows\setupact.log
2015-03-26 22:48 - 2015-03-26 22:48 - 00267904 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-26 22:48 - 2015-03-26 22:48 - 00000000 _____ () C:\Windows\setuperr.log
2015-03-26 15:28 - 2015-03-26 16:14 - 00000000 ____D () C:\Users\Dezika\Downloads\Bad.Ass.3.Bad.Asses.on.the.Bayou.2015.WEBRiP.AC3.x264-LEGi0N
2015-03-25 17:25 - 2015-03-25 17:26 - 00000000 ____D () C:\Users\Dezika\Downloads\Ass Backwards (2013)
2015-03-25 15:14 - 2015-03-11 04:30 - 00623616 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-03-25 15:14 - 2015-03-11 04:30 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-03-25 15:14 - 2015-03-11 04:29 - 00818176 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-03-25 15:14 - 2015-03-11 04:29 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-03-25 15:14 - 2015-03-11 04:29 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-03-25 15:14 - 2015-03-11 04:29 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-03-25 15:14 - 2015-03-11 04:29 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-03-25 15:14 - 2015-03-11 04:26 - 00892928 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-03-21 22:13 - 2015-03-21 22:14 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-03-17 21:29 - 2015-03-09 08:35 - 00000000 ____D () C:\Users\Dezika\Downloads\Kidnapping.Mr.Heineken.2015.720p.WEB-DL.700MB
2015-03-14 23:28 - 2015-03-14 23:28 - 00002079 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-03-14 23:28 - 2015-03-14 23:28 - 00000000 ____D () C:\Users\Dezika\AppData\Roaming\AVAST Software
2015-03-14 23:28 - 2015-03-14 23:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-03-14 23:27 - 2015-03-14 23:27 - 00788272 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-03-14 23:27 - 2015-03-14 23:27 - 00427480 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSP.sys
2015-03-14 23:27 - 2015-03-14 23:27 - 00291312 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-03-14 23:27 - 2015-03-14 23:27 - 00206976 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2015-03-14 23:27 - 2015-03-14 23:27 - 00106912 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys
2015-03-14 23:27 - 2015-03-14 23:27 - 00081728 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys
2015-03-14 23:27 - 2015-03-14 23:27 - 00073440 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-03-14 23:27 - 2015-03-14 23:27 - 00049904 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2015-03-14 23:27 - 2015-03-14 23:27 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-03-14 23:27 - 2015-03-14 23:27 - 00024144 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2015-03-14 23:26 - 2015-03-14 23:26 - 00000000 ____D () C:\Program Files\AVAST Software
2015-03-14 19:17 - 2015-03-14 20:09 - 00000586 _____ () C:\DelFix.txt
2015-03-14 15:07 - 2015-03-14 19:40 - 00000000 ____D () C:\Users\Dezika\Downloads\Torrente.3.El.Protector[DVDRip][Spanish][WwW.DivXaTope.CoM]
2015-03-14 15:05 - 2015-03-14 20:08 - 00000000 ____D () C:\Users\Dezika\Downloads\Torrente 2 - Mision En Marbella (2001)
2015-03-14 15:05 - 2015-03-14 19:42 - 00000000 ____D () C:\Users\Dezika\Downloads\Torrente 4 [dvdrip][spanish][AC35.1][www.lokotorrents.com]
2015-03-14 15:03 - 2015-03-14 20:01 - 00000000 ____D () C:\Users\Dezika\Downloads\Torrente 1 - El Brazo Tonto De La Ley (1998)
2015-03-11 23:01 - 2015-03-12 00:35 - 00000000 ____D () C:\Users\Dezika\Downloads\Exodus Gods and Kings (2014) [1080p]
2015-03-11 22:04 - 2015-03-11 22:04 - 00000000 ____D () C:\Users\Dezika\AppData\Local\VirtualStore
2015-03-11 21:50 - 2015-03-27 17:04 - 00000000 ____D () C:\Users\Dezika\AppData\Local\Popcorn-Time
2015-03-11 21:39 - 2015-03-11 21:39 - 00002218 _____ () C:\Users\Dezika\Desktop\Popcorn Time.lnk
2015-03-11 21:39 - 2015-03-11 21:39 - 00000000 ____D () C:\Users\Dezika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Popcorn Time
2015-03-11 21:39 - 2015-03-11 21:39 - 00000000 ____D () C:\Users\Dezika\AppData\Local\Popcorn Time
2015-03-11 19:41 - 2015-03-11 19:41 - 00000000 ____D () C:\Users\Dezika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-03-11 18:24 - 2015-03-11 18:24 - 00000000 ____D () C:\Windows\system32\vbox
2015-03-11 14:16 - 2015-02-26 04:11 - 02381312 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-03-11 14:16 - 2015-02-24 03:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-03-11 14:16 - 2015-02-21 01:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-03-11 14:16 - 2015-02-21 01:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-03-11 14:16 - 2015-02-21 01:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-03-11 14:16 - 2015-02-21 01:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-03-11 14:16 - 2015-02-21 00:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-03-11 14:16 - 2015-02-20 03:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-03-11 14:16 - 2015-02-20 03:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-03-11 14:16 - 2015-02-20 03:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-03-11 14:16 - 2015-02-20 03:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-03-11 14:16 - 2015-02-20 03:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-03-11 14:16 - 2015-02-20 03:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-03-11 14:16 - 2015-02-20 03:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-03-11 14:16 - 2015-02-20 03:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-03-11 14:16 - 2015-02-20 03:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-03-11 14:16 - 2015-02-20 02:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-03-11 14:16 - 2015-02-20 02:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-03-11 14:16 - 2015-02-20 02:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-03-11 14:16 - 2015-02-20 02:56 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-03-11 14:16 - 2015-02-20 02:50 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-11 14:16 - 2015-02-20 02:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-11 14:16 - 2015-02-20 02:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-03-11 14:16 - 2015-02-20 02:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-03-11 14:16 - 2015-02-20 02:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-03-11 14:16 - 2015-02-20 02:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-03-11 14:16 - 2015-02-20 02:24 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-03-11 14:16 - 2015-02-20 02:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-03-11 14:16 - 2015-02-20 02:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-03-11 14:16 - 2015-02-20 01:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-03-11 14:16 - 2015-02-20 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-03-11 14:16 - 2015-02-13 06:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-03-11 14:16 - 2015-02-03 04:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-03-11 14:16 - 2015-02-03 04:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-03-11 14:16 - 2015-01-31 04:32 - 00919552 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-03-11 14:16 - 2015-01-31 03:52 - 00134656 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2015-03-11 14:16 - 2015-01-31 03:51 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2015-03-11 14:16 - 2015-01-17 03:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-03-11 14:15 - 2015-03-06 06:15 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-03-11 14:15 - 2015-03-06 06:15 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-03-11 14:15 - 2015-03-06 06:10 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-03-11 14:15 - 2015-03-06 06:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-03-11 14:15 - 2015-03-06 06:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-03-11 14:15 - 2015-03-06 06:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-03-11 14:15 - 2015-03-06 06:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-03-11 14:15 - 2015-03-06 06:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-03-11 14:15 - 2015-03-06 06:10 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-03-11 14:15 - 2015-03-06 06:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-03-11 14:15 - 2015-03-06 06:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-03-11 14:15 - 2015-03-06 06:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-03-11 14:15 - 2015-03-06 06:10 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-03-11 14:15 - 2015-03-06 06:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-03-11 14:15 - 2015-03-06 06:09 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-03-11 14:15 - 2015-03-06 06:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-03-11 14:15 - 2015-03-06 06:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-03-11 14:15 - 2015-03-06 06:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-03-11 14:15 - 2015-02-20 05:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-03-11 14:15 - 2015-02-20 05:13 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-03-11 14:15 - 2015-02-20 05:13 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-03-11 14:15 - 2015-02-20 05:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-03-11 14:15 - 2015-02-20 04:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-03-11 14:15 - 2015-02-04 03:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-03-11 14:15 - 2015-02-03 04:16 - 03973048 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-03-11 14:15 - 2015-02-03 04:16 - 03917760 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-03-11 14:15 - 2015-02-03 04:16 - 00078784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-03-11 14:15 - 2015-02-03 04:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-03-11 14:15 - 2015-02-03 04:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-03-11 14:15 - 2015-02-03 04:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-03-11 14:15 - 2015-02-03 04:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-03-11 14:15 - 2015-02-03 04:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-03-11 14:15 - 2015-02-03 04:11 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-03-11 14:15 - 2015-02-03 04:11 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2015-03-11 14:15 - 2015-02-03 04:11 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-03-11 14:15 - 2015-02-03 04:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2015-03-11 14:15 - 2015-02-03 04:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2015-03-11 14:15 - 2015-02-03 04:11 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-03-11 14:15 - 2015-02-03 04:11 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2015-03-11 14:15 - 2015-02-03 04:11 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2015-03-11 14:15 - 2015-02-03 04:10 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2015-03-11 14:15 - 2015-02-03 04:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2015-03-11 14:15 - 2015-02-03 04:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-03-11 14:15 - 2015-02-03 04:00 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2015-03-11 14:15 - 2015-02-03 03:26 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-03-11 14:15 - 2015-01-31 00:56 - 00370488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-03-11 14:15 - 2014-10-31 23:22 - 00521384 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-03-11 14:15 - 2014-06-28 01:21 - 00455752 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2015-03-11 14:15 - 2014-06-28 01:21 - 00409272 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-03-02 13:29 - 2015-03-02 13:29 - 00000853 _____ () C:\Users\Dezika\Desktop\µTorrent.lnk

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-28 00:47 - 2015-02-18 21:23 - 00000000 ____D () C:\Users\Dezika\AppData\Roaming\uTorrent
2015-03-28 00:21 - 2015-02-05 13:44 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2015-03-28 00:21 - 2015-02-04 08:20 - 01502127 _____ () C:\Windows\WindowsUpdate.log
2015-03-28 00:20 - 2015-02-23 17:58 - 00000000 ____D () C:\Users\Dezika\AppData\Roaming\DAEMON Tools Lite
2015-03-27 23:49 - 2015-02-12 10:34 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-03-27 11:41 - 2009-07-14 05:34 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-27 11:41 - 2009-07-14 05:34 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-27 11:33 - 2015-02-04 02:06 - 00000000 ____D () C:\Users\Dezika\AppData\Roaming\Skype
2015-03-27 11:32 - 2015-02-06 17:15 - 00000000 ____D () C:\ProgramData\MCShield
2015-03-27 11:31 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-26 14:50 - 2015-02-04 02:33 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-03-26 14:50 - 2015-02-04 02:33 - 00000000 ____D () C:\Windows\system32\appraiser
2015-03-24 20:52 - 2015-01-25 00:09 - 00000000 ____D () C:\Users\Dezika\Downloads\Interstellar
2015-03-24 20:49 - 2015-01-29 11:46 - 00000000 ____D () C:\Users\Dezika\Downloads\Torrente
2015-03-24 20:48 - 2015-02-20 16:08 - 00000000 ____D () C:\Users\Dezika\Downloads\Peter.Pan.Return.To.Neverland.DVDRip.XviD-DEiTY
2015-03-23 14:58 - 2015-02-04 08:27 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-03-19 23:40 - 2010-11-20 22:01 - 00778834 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-03-15 00:34 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2015-03-14 23:33 - 2015-02-05 23:28 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-03-14 23:33 - 2015-02-05 23:28 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-03-14 23:25 - 2015-02-12 10:28 - 00000000 ____D () C:\ProgramData\AVAST Software
2015-03-14 23:25 - 2015-02-04 01:37 - 00000000 ____D () C:\Windows\system32\MRT
2015-03-14 23:21 - 2015-02-04 01:36 - 119837696 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-03-14 17:03 - 2015-02-04 02:37 - 00000000 ____D () C:\Users\Dezika\AppData\Roaming\Winamp
2015-03-11 21:55 - 2015-02-06 00:43 - 00000000 ____D () C:\Users\Dezika\AppData\Local\Macromedia
2015-03-11 21:19 - 2015-02-04 08:24 - 00000000 ____D () C:\Users\Dezika
2015-03-11 20:59 - 2015-02-09 18:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Popcorn Time
2015-03-11 19:41 - 2015-02-04 00:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-03-11 19:41 - 2015-02-04 00:34 - 00000000 ____D () C:\Program Files\WinRAR
2015-03-05 18:10 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\NDF
2015-03-04 19:30 - 2010-11-21 01:46 - 00000000 ___RD () C:\Users\Public\Recorded TV

Some content of TEMP:
====================
C:\Users\Dezika\AppData\Local\Temp\dt_352E.tmp.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-03-26 00:03

==================== End Of Log ============================

https://www.mycity.rs/must-login.png

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Arrow Korak 1

Otvori Notepad i iskopiraj sljedeći tekst koji se nalazi unutar Kod polja.

HKU\S-1-5-21-3609390036-2450797130-3040472919-1000\...\MountPoints2: {030dcc60-bb49-11e4-a925-0015831080cf} - G:\BlacklistAutoRun.exe
HKU\S-1-5-21-3609390036-2450797130-3040472919-1000\...\MountPoints2: {e2cf5ba3-ac3d-11e4-9402-806e6f6e6963} - F:\setup.exe
FF DefaultSearchEngine: Google (avast)
FF SearchPlugin: C:\Users\Dezika\AppData\Roaming\Mozilla\Firefox\Profiles\1kvknn5z.default\searchplugins\google-avast.xml [2015-02-12]
Task: {3261E6E4-40D0-4025-9E7B-4606BCD78540} - \{B258D161-54E5-4742-A7E0-275F8D8A90D3} No Task File <==== ATTENTION
EmptyTemp:


U okviru Notepad-a klikni na File --> Save As
Fajl nazovi Fixlist i sačuvaj na Desktop
Dvoklikom ponovo pokreni FRST.exe
Klikni na Fix i sačekaj dok program ne završi.
Ukoliko program zatraži restart računara, omogući mu da to nesmetano obavi.
Nakon završetka rada, otvoriće se fixlog.txt, sa sadržajem koji treba da kopiraš u temu.
Takođe, na Desktop-u će se nalaziti (fixlog.txt).




Arrow Korak 2

Preuzmi "Xplode"-ov AdwCleaner i sačuvaj ga na Desktop
Dvoklikom pokreni program.
u EULA prozoru klikni na I agree.
Klikni na dugme Scan i sačekaj da se završi skeniranje.
Klikni na dugme Clean i pričekaj da program završi.
Program će zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni OK kao potvrdu.
Na sljedeća dva prozora koja se otvore (Informations i Restart required ) klikni OK

Računar će se restartovati, a potom otvoriti Notepad (C:\AdwCleaner[S0].txt) sa izvještajem.
Sačuvaj taj izvještaj na Desktop i okači ga uz poruku koristeći opciju "Prikači fajl"

Napomena: Izvještaj ce takođe biti sačuvan na C:\Adwcleaner\AdwCleaner[S0].txt

offline
  • Pridružio: 10 Jan 2015
  • Poruke: 202
  • Gde živiš: Novi Sad

Napisano: 29 Mar 2015 15:17

Sass hvala ali sam izbrisao neke stavke posto nisam mogao na internet,blokiralo mi je skroz,dok nisam izbrisao iz sistema neke fajlove zzzzz tako nesto i firefox,ali mi stoji u kanti da nije uspelo da ga izbrise




morao sam ovo da uradim da bi povratio net,ako mozes da mi kazes sta sad da uradim jer mi se promenilo dosta stvari ?da postavim novi izvestaj?

Dopuna: 29 Mar 2015 15:19

radio sam i system restore ali uzalud izbaci mi da ne moze da vrati neka greska ali vidim da mi fajlovi neki fale kao da uradi ali izbaci gresku i nemam opet net tako da sam to uzalud radio

Dopuna: 29 Mar 2015 15:26

nece da udje uopste ni u frst ni u adwcleaner zablokira odobravanje

Dopuna: 29 Mar 2015 15:40

evo uspeo sam u safe modu da odradim
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 11-03-2015
Ran by Dezika at 2015-03-29 15:33:34 Run:1
Running from C:\Users\Dezika\Desktop
Loaded Profiles: Dezika (Available profiles: Dezika)
Boot Mode: Safe Mode (minimal)

==============================================

Content of fixlist:
*****************
HKU\S-1-5-21-3609390036-2450797130-3040472919-1000\...\MountPoints2: {030dcc60-bb49-11e4-a925-0015831080cf} - G:\BlacklistAutoRun.exe
HKU\S-1-5-21-3609390036-2450797130-3040472919-1000\...\MountPoints2: {e2cf5ba3-ac3d-11e4-9402-806e6f6e6963} - F:\setup.exe
FF DefaultSearchEngine: Google (avast)
FF SearchPlugin: C:\Users\Dezika\AppData\Roaming\Mozilla\Firefox\Profiles\1kvknn5z.default\searchplugins\google-avast.xml [2015-02-12]
Task: {3261E6E4-40D0-4025-9E7B-4606BCD78540} - \{B258D161-54E5-4742-A7E0-275F8D8A90D3} No Task File <==== ATTENTION
EmptyTemp:
*****************

"HKU\S-1-5-21-3609390036-2450797130-3040472919-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{030dcc60-bb49-11e4-a925-0015831080cf}" => Key deleted successfully.
HKCR\CLSID\{030dcc60-bb49-11e4-a925-0015831080cf} => Key not found.
"HKU\S-1-5-21-3609390036-2450797130-3040472919-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e2cf5ba3-ac3d-11e4-9402-806e6f6e6963}" => Key deleted successfully.
HKCR\CLSID\{e2cf5ba3-ac3d-11e4-9402-806e6f6e6963} => Key not found.
Firefox DefaultSearchEngine deleted successfully.
C:\Users\Dezika\AppData\Roaming\Mozilla\Firefox\Profiles\1kvknn5z.default\searchplugins\google-avast.xml => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3261E6E4-40D0-4025-9E7B-4606BCD78540}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3261E6E4-40D0-4025-9E7B-4606BCD78540}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B258D161-54E5-4742-A7E0-275F8D8A90D3}" => Key deleted successfully.
EmptyTemp: => Removed 38.5 MB temporary data.


The system needed a reboot.

==== End of Fixlog 15:33:36 ====

Dopuna: 29 Mar 2015 15:46

evo odradio sam ovo u safe modu

https://www.mycity.rs/must-login.png

https://www.mycity.rs/must-login.png

Dopuna: 29 Mar 2015 16:28

ovo je nasao tdsskiller

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

NIsam ti rekao da koristiš TDSSKiller niti sam ti rekao da brišeš fajlove iz sistema. Šta si tačno izbrisao?

offline
  • Pridružio: 10 Jan 2015
  • Poruke: 202
  • Gde živiš: Novi Sad

Napisano: 30 Mar 2015 2:10

neki fajl u rar arhivi i nzm sta jos ali sve je bilo pod nazivom ZZZZZZZZZZ i firefox u sistemu nisam nista ostetio radi sve i net

Dopuna: 30 Mar 2015 2:11

morao sam da obrisem nisam imao uopste net tako da nisam mogao da skidam ni frst niti da vidim sta si pisao jer mi je blokiralo i wifi

Dopuna: 30 Mar 2015 2:13

U system folderu da te ne zbuni,sto se nalazi vezano za firefox

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Preuzmi zoek.exe sa ovog ili ovog linka i sačuvaj ga na Desktop.


Zatvori browser i ostale pokrenute programe;
deaktiviraj zaštitni softver ( po potrebi ) Uputstvo ;
dvoklikom pokreni zoek.exe;
pričekaj da se alat startuje ...


U beli okvir prozora iskopiraj sljedeći tekst:

process;
startupall;
drivers-services-list;
skipfix-iedefaults;
firefoxlook;
chromelook;
filesrcm;


Klikni na dugme i pričekaj da se skeniranje završi.


Zoek će po potrebi restartovati Windows, a na kraju rada otvoriti Notepad sa izvještajem o skeniranju.

Napomena: Izvještaj će biti sačuvan pod nazivom zoek-results.log na sistemskoj particiji (tipična lokacija: C:\zoek-results.log)


Arrow Kopiraj sadržaj tog loga u poruku.

offline
  • Pridružio: 10 Jan 2015
  • Poruke: 202
  • Gde živiš: Novi Sad

odradio
https://www.mycity.rs/must-login.png


Zoek.exe v5.0.0.0 Updated 29-March-2015
Tool run by Dezika on Mon 03/30/2015 at 23:46:42.37.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Dezika\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

3/30/2015 11:48:45 PM Zoek.exe System Restore Point Created Successfully.

==== Running Processes ======================

C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
C:\Program Files\TeamViewer\TeamViewer_Service.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
C:\Windows\system32\conhost.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\MCShield\MCShieldRTM.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil VoIP Plugin.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Windows\system32\vssvc.exe
C:\Users\Dezika\Desktop\zoek.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k swprv

==== Services(whitelist) ======================
Powered by E Dev

R2 - [AdobeARMservice] - Adobe Acrobat Update Service - c:\program files\common files\adobe\arm\1.0\armsvc.exe
R2 - [NvNetworkService] - NVIDIA Network Service - c:\program files\nvidia corporation\netservice\nvnetworkservice.exe
R2 - [NvStreamSvc] - NVIDIA Streamer Service - c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe
R2 - [nvsvc] - NVIDIA Display Driver Service - c:\windows\system32\nvvsvc.exe
R2 - [TeamViewer] - TeamViewer 10 - c:\program files\teamviewer\teamviewer_service.exe
R2 - [WMPNetworkSvc] - Windows Media Player Network Sharing Service - c:\program files\windows media player\wmpnetwk.exe
R2 - [WSearch] - Windows Search - c:\windows\system32\searchindexer.exe
R3 - [AvastVBoxSvc] - AvastVBox COM Service - c:\program files\avast software\avast\ng\vbox\avastvboxsvc.exe
R3 - [VSS] - Volume Shadow Copy - c:\windows\system32\vssvc.exe
R4 - [BlueSoleil Hid Service] - BlueSoleil Hid Service - c:\program files\ivt corporation\bluesoleil\btntservice.exe
R4 - [Start BT in service] - Start BT in service - c:\program files\ivt corporation\bluesoleil\startskysolsvc.exe
S2 - [clr_optimization_v4.0.30319_32] - Microsoft .NET Framework NGEN v4.0.30319_X86 - c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
S2 - [sppsvc] - Software Protection - c:\windows\system32\sppsvc.exe
S3 - [AdobeFlashPlayerUpdateSvc] - Adobe Flash Player Update Service - c:\windows\system32\macromed\flash\flashplayerupdateservice.exe
S3 - [ALG] - Application Layer Gateway Service - c:\windows\system32\alg.exe
S3 - [aspnet_state] - ASP.NET State Service - c:\windows\microsoft.net\framework\v4.0.30319\aspnet_state.exe
S3 - [COMSysApp] - COM+ System Application - c:\windows\system32\dllhost.exe
S3 - [ehRecvr] - Windows Media Center Receiver Service - c:\windows\ehome\ehrecvr.exe
S3 - [ehSched] - Windows Media Center Scheduler Service - c:\windows\ehome\ehsched.exe
S3 - [Fax] - Fax - c:\windows\system32\fxssvc.exe
S3 - [FontCache3.0.0.0] - Windows Presentation Foundation Font Cache 3.0.0.0 - c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe
S3 - [gusvc] - Google Updater Service - c:\program files\google\common\google updater\googleupdaterservice.exe [x]
S3 - [IEEtwCollectorService] - Internet Explorer ETW Collector Service - c:\windows\system32\ieetwcollector.exe
S3 - [MozillaMaintenance] - Mozilla Maintenance Service - c:\program files\mozilla maintenance service\maintenanceservice.exe
S3 - [MSDTC] - Distributed Transaction Coordinator - c:\windows\system32\msdtc.exe
S3 - [msiserver] - Windows Installer - c:\windows\system32\msiexec.exe
S3 - [RpcLocator] - Remote Procedure Call (RPC) Locator - c:\windows\system32\locator.exe
S3 - [SNMPTRAP] - SNMP Trap - c:\windows\system32\snmptrap.exe
S3 - [TrustedInstaller] - Windows Modules Installer - c:\windows\servicing\trustedinstaller.exe
S3 - [vds] - Virtual Disk - c:\windows\system32\vds.exe
S3 - [wbengine] - Block Level Backup Engine Service - c:\windows\system32\wbengine.exe
S3 - [wmiApSrv] - WMI Performance Adapter - c:\windows\system32\wbem\wmiapsrv.exe
S4 - [clr_optimization_v2.0.50727_32] - Microsoft .NET Framework NGEN v2.0.50727_X86 - c:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.exe
S4 - [SkypeUpdate] - Skype Updater - c:\program files\skype\updater\updater.exe

==== Drivers(whitelist) ======================
Powered by E Dev

R0 - [FileInfo] - File Information FS MiniFilter - C:\Windows\system32\Drivers\FileInfo.sys
R0 - [FltMgr] - FltMgr - C:\Windows\system32\Drivers\FltMgr.sys
R0 - [Mup] - Mup - C:\Windows\system32\Drivers\Mup.sys
R1 - [NetBIOS] - NetBIOS Interface - C:\Windows\system32\Drivers\NetBIOS.sys
R3 - [srv] - Server SMB 1.xxx Driver - C:\Windows\system32\Drivers\srv.sys
R3 - [srv2] - Server SMB 2.xxx Driver - C:\Windows\system32\Drivers\srv2.sys
R0 - [ACPI] - Microsoft ACPI Driver - C:\Windows\system32\Drivers\ACPI.sys
R0 - [amdxata] - amdxata - C:\Windows\system32\Drivers\amdxata.sys
R0 - [aswRvrt] - avast! Revert - C:\Windows\system32\Drivers\aswRvrt.sys
R0 - [aswVmm] - avast! VM Monitor - C:\Windows\system32\Drivers\aswVmm.sys
R0 - [atapi] - IDE Channel - C:\Windows\system32\Drivers\atapi.sys
R0 - [BTHidEnum] - Bluetooth HID Enumerator - C:\Windows\system32\Drivers\BTHidEnum.sys [x]
R0 - [BTHidMgr] - Bluetooth HID Manager Service - C:\Windows\system32\Drivers\BTHidMgr.sys
R0 - [CLFS] - Common Log (CLFS) - C:\Windows\system32\Drivers\CLFS.sys [x]
R0 - [CNG] - CNG - C:\Windows\system32\Drivers\CNG.sys
R0 - [Disk] - Disk Driver - C:\Windows\system32\Drivers\Disk.sys
R0 - [fvevol] - Bitlocker Drive Encryption Filter Driver - C:\Windows\system32\Drivers\fvevol.sys
R0 - [giveio] - giveio - C:\Windows\system32\Drivers\giveio.sys [x]
R0 - [hwpolicy] - Hardware Policy Driver - C:\Windows\system32\Drivers\hwpolicy.sys
R0 - [intelide] - intelide - C:\Windows\system32\Drivers\intelide.sys
R0 - [KSecDD] - KSecDD - C:\Windows\system32\Drivers\KSecDD.sys
R0 - [KSecPkg] - KSecPkg - C:\Windows\system32\Drivers\KSecPkg.sys
R0 - [mountmgr] - Mount Point Manager - C:\Windows\system32\Drivers\mountmgr.sys
R0 - [msisadrv] - msisadrv - C:\Windows\system32\Drivers\msisadrv.sys
R0 - [NDIS] - NDIS System Driver - C:\Windows\system32\Drivers\NDIS.sys
R0 - [partmgr] - Partition Manager - C:\Windows\system32\Drivers\partmgr.sys
R0 - [pci] - PCI Bus Driver - C:\Windows\system32\Drivers\pci.sys
R0 - [pcw] - Performance Counters for Windows Driver - C:\Windows\system32\Drivers\pcw.sys
R0 - [rdyboost] - ReadyBoost - C:\Windows\system32\Drivers\rdyboost.sys
R0 - [speedfan] - speedfan - C:\Windows\system32\Drivers\speedfan.sys [x]
R0 - [spldr] - Security Processor Loader Driver - C:\Windows\system32\Drivers\spldr.sys
R0 - [storflt] - Disk Virtual Machine Bus Acceleration Filter Driver - C:\Windows\system32\Drivers\storflt.sys [x]
R0 - [Tcpip] - TCP/IP Protocol Driver - C:\Windows\system32\Drivers\Tcpip.sys
R0 - [vdrvroot] - Microsoft Virtual Drive Enumerator Driver - C:\Windows\system32\Drivers\vdrvroot.sys
R0 - [volmgr] - Volume Manager Driver - C:\Windows\system32\Drivers\volmgr.sys
R0 - [volmgrx] - Dynamic Volume Manager - C:\Windows\system32\Drivers\volmgrx.sys
R0 - [volsnap] - Storage volumes - C:\Windows\system32\Drivers\volsnap.sys
R0 - [Wdf01000] - Kernel Mode Driver Frameworks service - C:\Windows\system32\Drivers\Wdf01000.sys
R1 - [AFD] - Ancillary Function Driver for Winsock - C:\Windows\system32\Drivers\AFD.sys
R1 - [Beep] - Beep - C:\Windows\system32\Drivers\Beep.sys
R1 - [tdx] - NetIO Legacy TDI Support Driver - C:\Windows\system32\Drivers\tdx.sys
R2 - [tcpipreg] - TCP/IP Registry Compatibility - C:\Windows\system32\Drivers\tcpipreg.sys

==== Files Recently Created / Modified ======================

====== C:\Windows ====
2015-03-14 22:27:40 C4B680AA8A352611D0C70E680A87E367 43112 ----a-w- C:\Windows\avastSS.scr
====== C:\Users\Dezika\AppData\Local\Temp ====
====== Java Cache =====
====== C:\Windows\system32 =====
2015-03-29 13:40:11 46E863AB492069BD049CA71BC21C0474 291312 ----a-w- C:\Windows\System32\aswBoot.exe
2015-03-25 14:14:08 373D75CA475CFD554D60665F3FB4DD8F 159744 ----a-w- C:\Windows\System32\aepic(75).dll
====== C:\Windows\system32\drivers =====
2015-03-29 14:36:11 04B309A1A653177994630C2773E659F1 119512 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2015-03-29 14:35:46 F88B3A1CA0CE7DA9879F633D3EC10B9B 92888 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2015-03-29 13:40:15 F761D13D43D0F4FB2986308CFFD7F589 106912 ----a-w- C:\Windows\System32\drivers\aswB0B0.tmp
2015-03-29 13:40:15 2EBD0ACCAFC67088D4B9EBDF7428F6AD 206976 ----a-w- C:\Windows\System32\drivers\aswAFB5.tmp
2015-03-29 13:40:14 E5F230B70F1A9764EB7AC4A76445F79F 427480 ----a-w- C:\Windows\System32\drivers\aswAD63.tmp
2015-03-29 13:40:14 6FB92505DAA300DA62A1C374B949B574 49904 ----a-w- C:\Windows\System32\drivers\aswAC0B.tmp
2015-03-29 13:40:13 C3A047ABB97AEB805E07A30EFDACD0B9 788272 ----a-w- C:\Windows\System32\drivers\aswA7E2.tmp
2015-03-29 13:40:13 AA69ED00EE72BFEE003C864DCFBC5038 24144 ----a-w- C:\Windows\System32\drivers\aswAA83.tmp
2015-03-29 13:40:13 6FDAE6458E0FAC369005EEFE55E1190A 73440 ----a-w- C:\Windows\System32\drivers\aswAB30.tmp
2015-03-29 13:40:13 0BD1C9E546CA7D801E25FED0E9CA58B8 81728 ----a-w- C:\Windows\System32\drivers\aswA9A8.tmp
2015-03-14 22:27:50 F761D13D43D0F4FB2986308CFFD7F589 106912 ----a-w- C:\Windows\System32\drivers\aswStm.sys
2015-03-14 22:27:50 E5F230B70F1A9764EB7AC4A76445F79F 427480 ----a-w- C:\Windows\System32\drivers\aswSP.sys
2015-03-14 22:27:50 6FB92505DAA300DA62A1C374B949B574 49904 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2015-03-14 22:27:50 2EBD0ACCAFC67088D4B9EBDF7428F6AD 206976 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2015-03-14 22:27:49 AA69ED00EE72BFEE003C864DCFBC5038 24144 ----a-w- C:\Windows\System32\drivers\aswHwid.sys
2015-03-14 22:27:49 6FDAE6458E0FAC369005EEFE55E1190A 73440 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2015-03-14 22:27:48 0BD1C9E546CA7D801E25FED0E9CA58B8 81728 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2015-03-14 22:27:47 C3A047ABB97AEB805E07A30EFDACD0B9 788272 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2015-03-11 13:16:37 83EE20D7160484C9172FDF0ACBDC8929 15872 ----a-w- C:\Windows\System32\drivers\rdpvideominiport.sys
2015-03-11 13:15:56 9EED5E0B7BF784C491C2289A09920BDA 137656 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2015-03-11 13:15:56 4DAC97CF81FAE4B2988AEF0DF40D04AE 67512 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2015-03-11 13:15:44 AEBC369F7DC72AB3F5B9BDF34FA0D43F 593920 ----a-w- C:\Windows\System32\drivers\PEAuth.sys
2015-03-11 13:15:43 644905A19D0F37F2233DFCE53BC4BC19 78784 ----a-w- C:\Windows\System32\drivers\mountmgr.sys
2015-03-11 13:15:43 3051724F223EA48968B19567DE2A81F4 370488 ----a-w- C:\Windows\System32\drivers\cng.sys
2015-03-11 13:15:41 81F97D8F8B3FB94A451CC6F7CF8B2965 50176 ----a-w- C:\Windows\System32\drivers\appid.sys
====== C:\Windows\Tasks ======
2015-03-14 22:28:03 0FA880995DBCE08DDCC9466843446F45 3924 ----a-w- C:\Windows\system32\Tasks\avast! Emergency Update
====== C:\Windows\Temp ======
======= C:\Program Files =====
======= C: =====
2015-03-14 18:17:40 91937CD0129838F79291D26CF6EE248B 586 ----a-w- C:\DelFix.txt
====== C:\Users\Dezika\AppData\Roaming ======
2015-03-29 14:17:03 -------- d-----w- C:\Users\Dezika\AppData\Local\ElevatedDiagnostics
2015-03-29 13:15:38 160675A26FADEB42B352C75C8094EC05 57960 ----a-w- C:\Users\Dezika\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-29 12:10:59 407AAB8C27CF7081EECE071C90A65B83 17 ----a-w- C:\Users\Dezika\AppData\Local\resmon.resmoncfg
2015-03-27 19:15:04 -------- d-----w- C:\Users\Dezika\AppData\Roaming\Far Cry 3
2015-03-11 21:04:16 -------- d-----w- C:\Users\Dezika\AppData\Local\VirtualStore
2015-03-11 20:50:15 -------- d-----w- C:\Users\Dezika\AppData\Local\Popcorn-Time
2015-03-11 20:39:47 -------- d-----w- C:\Users\Dezika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Popcorn Time
2015-03-11 20:39:11 -------- d-----w- C:\Users\Dezika\AppData\Local\Popcorn Time
2015-03-11 18:41:52 -------- d-----w- C:\Users\Dezika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-03-04 18:30:57 -------- d-s---w- C:\Windows\serviceprofiles\networkservice\AppData\Locallow\Microsoft
====== C:\Users\Dezika ======
2015-03-29 14:34:56 56A375A83CED75C331A67882D0C0F9DA 16502728 ----a-w- C:\Users\Dezika\Downloads\mbar-1.09.1.1004.exe
2015-03-29 14:24:18 9C5DAAED3B3C06DBC95228CC407B8B70 4197016 ----a-w- C:\Users\Dezika\Downloads\tdsskiller.exe
2015-03-29 13:23:49 E55CCE4E4A0153A3122E76A3DA23B288 2168320 ----a-w- C:\Users\Dezika\Downloads\AdwCleaner.exe
2015-03-29 13:23:17 67D890E8DA0A5DB2846B6366172D15A0 1135104 ----a-w- C:\Users\Dezika\Desktop\FRST.exe
2015-03-27 19:26:45 -------- d-----w- C:\ProgramData\Orbit
2015-03-27 19:14:14 -------- d-----w- C:\ProgramData\Package Cache

====== C: exe-files ==
2015-03-30 20:06:02 091D04129C8DA68A6563364EF0E509D8 36672136 ----a-w- C:\ProgramData\NVIDIA Corporation\NetService\254af330-6780-4cfe-a3e3-913906ee4e33\GeForce_Experience_Update_v2.4.1.21.exe
2015-03-29 14:35:45 FE9BD656A5F251D2BB90151325DA1B14 54072 ----a-w- C:\Users\Dezika\Desktop\mbar\mbamdor.exe
2015-03-29 14:35:45 7CBC1070E51238E59F7535C8F2344FB6 821560 ----a-w- C:\Users\Dezika\Desktop\mbar\Plugins\fixdamage.exe
2015-03-29 14:35:45 5E29C495F48A9CFED856D097FED6ECE4 170296 ----a-w- C:\Users\Dezika\Desktop\mbar\mbar.exe
2015-03-29 14:34:56 56A375A83CED75C331A67882D0C0F9DA 16502728 ----a-w- C:\Users\Dezika\Downloads\mbar-1.09.1.1004.exe
2015-03-29 14:24:18 9C5DAAED3B3C06DBC95228CC407B8B70 4197016 ----a-w- C:\Users\Dezika\Downloads\tdsskiller.exe
2015-03-29 13:40:11 46E863AB492069BD049CA71BC21C0474 291312 ----a-w- C:\Windows\System32\aswBoot.exe
2015-03-29 13:23:49 E55CCE4E4A0153A3122E76A3DA23B288 2168320 ----a-w- C:\Users\Dezika\Downloads\AdwCleaner.exe
2015-03-29 13:23:17 67D890E8DA0A5DB2846B6366172D15A0 1135104 ----a-w- C:\Users\Dezika\Desktop\FRST.exe
2015-03-27 09:33:30 18975C321D5B780A4A502344CFFC6356 675256 ----a-w- C:\Users\Dezika\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
2015-03-27 09:33:26 94D94CECFECF61695F2EFBB9D44D84D2 172984 ----a-w- C:\Users\Dezika\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\OAWrapper.exe
2015-03-25 15:31:15 444EA843E5945BAF8E9AB0DA2E3FD09F 440440 ----a-w- C:\Users\Dezika\AppData\Local\NVIDIA\NvBackend\Packages\0000729d\CoProc update.19433226.exe
2015-03-24 15:30:14 7D51736F3FAA9F64A3934C9FE639DCA6 5286264 ----a-w- C:\Users\Dezika\AppData\Local\NVIDIA\NvBackend\Packages\00007293\DAO.19430125.exe
=== C: other files ==
2015-03-29 14:36:11 04B309A1A653177994630C2773E659F1 119512 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2015-03-29 14:35:46 F88B3A1CA0CE7DA9879F633D3EC10B9B 92888 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-21-3609390036-2450797130-3040472919-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"MCShield Monitor"="C:\Program Files\MCShield\mcshieldrtm.exe"
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\DTLite.exe -autorun"

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"="C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe"
"RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s"
"ShadowPlay"="C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart"
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MCShield Monitor"="C:\Program Files\MCShield\mcshieldrtm.exe"
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\DTLite.exe -autorun"

==== Startup Registry Disabled ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CCleaner Monitoring]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CCleaner Monitoring"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\CCleaner\\CCleaner.exe\" /MONITOR"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skype]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Skype"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /minimized /regrun"


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\BlueSoleil Hid Service]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Start BT in service]


==== Startup Folders ======================

2015-02-09 22:20:38 2075 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BlueSoleil.lnk

==== Task Scheduler Jobs ======================

C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [03/15/2015 12:33 AM]

==== Other Scheduled Tasks ======================

"C:\Windows\system32\tasks\Adobe Acrobat Update Task" [C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe]
"C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\Windows\system32\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"]
"C:\Windows\system32\tasks\SidebarExecute" [C:\Program Files\Windows Sidebar\sidebar.exe]
"C:\Windows\system32\tasks\{45AFEA6C-2242-4869-A01F-C9E48B209DCD}" [C:\Users\Dezika\Desktop\Counter-Strike.exe]

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Dezika\AppData\Roaming\Mozilla\Firefox\Profiles\1kvknn5z.default
user_pref("browser.startup.homepage", "https://www.google.com/?trackid=sp-006");
user_pref("browser.search.defaulturl", "https://www.google.com/search/?trackid=sp-006");
user_pref("browser.search.defaultengine", "Google (avast)");
user_pref("browser.search.selectedEngine", "Google (avast)");
user_pref("keyword.URL", "https://www.google.com/search/?trackid=sp-006");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [03/29/2015 04:49 PM]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Dezika\AppData\Roaming\Mozilla\Firefox\Profiles\1kvknn5z.default
- Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Dezika\AppData\Roaming\Mozilla\Firefox\Profiles\1kvknn5z.default
0806948270D853B709CCBBF38AF167E4 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat
9DF0C4F0CEF60158614EDD1B3AB441EE - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
A104717A0DB2BF3412B7CA51ECD8CCFD - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U76
08A8AA80E372A867D7979DA0949AC4BA - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.760.13
43583AB4DFD406F4C188342F41B1F91C - C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll - Shockwave Flash


==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[03/15/2015 12:27 AM]

==== IE Start and Search Settings ======================

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"

==== C:\zoek_backup content ======================

C:\zoek_backup (files=0 folders=0 0 bytes)

==== EOF on Mon 03/30/2015 at 23:52:04.06 ======================

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Ovo mi izgleda čisto no ipak:


Zatvori browser i ostale pokrenute programe;
deaktiviraj zaštitni softver ( po potrebi ) Uputstvo ;
dvoklikom pokreni zoek.exe;
pričekaj da se alat startuje ...


U beli okvir prozora iskopiraj sljedeći tekst:

emptyalltemp;
emptyclsid;
autoclean;


Klikni na dugme i pričekaj da se skeniranje završi.


Zoek će po potrebi restartovati Windows, a na kraju rada otvoriti Notepad sa izvještajem o skeniranju.

Napomena: Izvještaj će biti sačuvan pod nazivom zoek-results.log na sistemskoj particiji (tipična lokacija: C:\zoek-results.log)


Arrow Kopiraj sadržaj tog loga u poruku.

offline
  • Pridružio: 10 Jan 2015
  • Poruke: 202
  • Gde živiš: Novi Sad

Zoek.exe v5.0.0.0 Updated 29-March-2015
Tool run by Dezika on Tue 03/31/2015 at 23:56:09.54.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Dezika\Desktop\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2015-03-30-215204.log 23768 bytes
C:\zoek-results2015-03-30-221448.log 23682 bytes

==== Empty Folders Check ======================

C:\PROGRA~2\Malwarebytes' Anti-Malware (portable) deleted successfully
C:\PROGRA~2\SpeedBit deleted successfully
C:\Users\Dezika\AppData\Local\VirtualStore deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gusvc deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\gusvc deleted successfully

==== Deleting Files \ Folders ======================

C:\PROGRA~2\Malwarebytes' Anti-Malware (portable) not found
C:\PROGRA~2\Package Cache deleted
C:\Windows\system32\config\systemprofile\Searches deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Dezika\AppData\Roaming\Mozilla\Firefox\Profiles\1kvknn5z.default
user_pref("browser.startup.homepage", "https://www.google.com/?trackid=sp-006");
user_pref("browser.search.defaulturl", "https://www.google.com/search/?trackid=sp-006");
user_pref("browser.search.defaultengine", "Google (avast)");
user_pref("browser.search.selectedEngine", "Google (avast)");
user_pref("keyword.URL", "https://www.google.com/search/?trackid=sp-006");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [03/29/2015 04:49 PM]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Dezika\AppData\Roaming\Mozilla\Firefox\Profiles\1kvknn5z.default
- Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Dezika\AppData\Roaming\Mozilla\Firefox\Profiles\1kvknn5z.default
0806948270D853B709CCBBF38AF167E4 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat
9DF0C4F0CEF60158614EDD1B3AB441EE - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
A104717A0DB2BF3412B7CA51ECD8CCFD - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U76
08A8AA80E372A867D7979DA0949AC4BA - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.760.13
43583AB4DFD406F4C188342F41B1F91C - C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll - Shockwave Flash


==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[03/15/2015 12:27 AM]

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"

==== Empty IE Cache ======================

C:\Users\Dezika\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\Dezika\AppData\Local\Mozilla\Firefox\Profiles\1kvknn5z.default\cache2 emptied successfully

==== Empty Chrome Cache ======================

No Chrome User Data found

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=6 folders=5 3138 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Dezika\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Dezika\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on Wed 04/01/2015 at 0:11:22.78 ======================

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Kakvo je stanje sada?

Ko je trenutno na forumu
 

Ukupno su 782 korisnika na forumu :: 50 registrovanih, 7 sakrivenih i 725 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: airsuba, Amigdala, Areal84, babaroga, bigfoot, Bobrock1, bokisha253, Boris90, chica, darkangel, debeli, Denaya, Dorcolac, dragoljub11987, dushan, FOX, gasha, goxin, ikan, ILGromovnik, JimmyNapoli, laurusri, Leonov, Marko Marković, mercedesamg, Mi lao shu, mile23, MiroslavD, Mixelotti, Mlav, nemkea71, nuke92, pein, RJ, ruger357, ruma, sasa87, simazr, Sirius, Sićko, slonic_tonic, Srky Boy, Srle993, TheBeastOfMG, VJ, Vlad000, vlajkox, yrraf, yufighter, YugoSlav